Privacy Policy

Last updated: August 2026

Pealo ("we," "us," or "our") helps you never miss what matters by turning calendar events into real iOS alarms and letting you create alarms with your voice. This policy explains what data Pealo collects, why, and how it is handled.

What Pealo does

Pealo turns your calendar events into real alarms. It connects to Google Calendar or Microsoft Outlook via OAuth, detects new events through server-side webhooks, and schedules alarms on your iPhone — even when the app is closed, silenced, or locked.

Account and authentication

When you create an account, we generate a random user identifier and a bearer token stored in your device's Keychain. We do not collect your name, email address, or password. When you connect a calendar, we store the OAuth refresh token encrypted at rest (AES-256-GCM) on our server. We never store your Google or Microsoft password.

Calendar data

Event details (titles, times, locations) are fetched from your calendar provider in real time when a webhook notifies us of a change. We use this data solely to schedule your alarms. Event content is not stored on our server — it passes through and is discarded. We store only connection metadata: which calendars are linked and their sync status.

Voice alarm creation

When you use voice to create an alarm, speech recognition runs locally on your device using Apple's Speech framework. The audio never leaves your phone. Only the resulting text transcript is sent to our server, which forwards it to the Anthropic API for parsing into an alarm configuration. We do not log, store, or retain the transcript. Anthropic processes it under their API terms and does not use API inputs for model training.

Data stored on our server

Your user identifier, encrypted OAuth tokens for connected calendars, webhook channel registrations, and sync metadata. That is all. No calendar content, no voice recordings, no personal profile information.

Analytics

We may collect anonymous, aggregated usage analytics (such as which features are used and how often) to improve the app. This data cannot identify you personally. We do not serve advertisements.

Third-party services

Pealo uses the following third-party services, each governed by their own privacy policy: Google Calendar API (to sync events), Microsoft Graph API (to sync events), Anthropic API (to parse voice commands), Apple Push Notification service (to trigger alarm sync), and Railway (server hosting).

Data security

OAuth tokens are encrypted at rest using AES-256-GCM. All communication between the app, our server, and third-party services uses HTTPS/TLS. Bearer tokens are stored in the iOS Keychain.

Data retention and deletion

When you delete your account or disconnect a calendar, the associated tokens and metadata are permanently removed from our server. You can request full data deletion at any time by contacting us.

Data sharing and disclosure

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes. Google Calendar data received through the Google API is shared with, transferred to, or disclosed to the following parties, solely for the purpose of providing Pealo's core functionality:

No Google user data is shared with, transferred to, or disclosed to any other third party.

Google API Limited Use Disclosure

Pealo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Your rights (GDPR)

If you are in the European Economic Area, you have the right to access, rectify, or delete your personal data, and to restrict or object to its processing. Since we store only a random identifier and encrypted tokens with no personal profile, the most practical way to exercise these rights is to delete your account in the app or contact us. Our legal basis for processing is legitimate interest (providing the service you requested).

Children

Pealo is not directed at children under 13. We do not knowingly collect data from children.

Contact

Privacy questions: privacy@pealo.app

Grzegorz Mróz Ventures
Krajewskiego 1/29
01-520 Warszawa, Poland

Pealo („my") pomaga Ci nie przegapić tego, co ważne, zamieniając wydarzenia z kalendarza w prawdziwe alarmy iOS i umożliwiając tworzenie alarmów głosem. Ta polityka wyjaśnia, jakie dane Pealo zbiera, dlaczego i jak są przetwarzane.

Co robi Pealo

Pealo zamienia wydarzenia z kalendarza w prawdziwe alarmy. Łączy się z Google Calendar lub Microsoft Outlook przez OAuth, wykrywa nowe wydarzenia przez webhooki po stronie serwera i ustawia alarmy na Twoim iPhonie — nawet gdy aplikacja jest zamknięta, wyciszona lub zablokowana.

Konto i uwierzytelnianie

Przy tworzeniu konta generujemy losowy identyfikator użytkownika i token bearer przechowywany w Keychain urządzenia. Nie zbieramy Twojego imienia, adresu email ani hasła. Przy podłączeniu kalendarza przechowujemy token odświeżania OAuth zaszyfrowany w spoczynku (AES-256-GCM) na naszym serwerze. Nigdy nie przechowujemy Twojego hasła Google ani Microsoft.

Dane kalendarza

Szczegóły wydarzeń (tytuły, godziny, lokalizacje) są pobierane od dostawcy kalendarza w czasie rzeczywistym, gdy webhook powiadomi nas o zmianie. Używamy tych danych wyłącznie do ustawiania alarmów. Treść wydarzeń nie jest przechowywana na naszym serwerze — przechodzi przez niego i jest usuwana. Przechowujemy jedynie metadane połączenia: które kalendarze są połączone i ich status synchronizacji.

Tworzenie alarmów głosem

Gdy używasz głosu do tworzenia alarmu, rozpoznawanie mowy działa lokalnie na Twoim urządzeniu przy użyciu Apple Speech. Dźwięk nigdy nie opuszcza Twojego telefonu. Tylko wynikowy transkrypt tekstowy jest wysyłany na nasz serwer, który przekazuje go do API Anthropic w celu przetworzenia na konfigurację alarmu. Nie logujemy, nie przechowujemy ani nie zachowujemy transkryptu. Anthropic przetwarza go zgodnie z warunkami swojego API i nie wykorzystuje danych wejściowych API do trenowania modeli.

Dane przechowywane na serwerze

Twój identyfikator użytkownika, zaszyfrowane tokeny OAuth dla połączonych kalendarzy, rejestracje kanałów webhook i metadane synchronizacji. To wszystko. Żadnych treści kalendarza, nagrań głosowych ani danych profilu osobowego.

Analityka

Możemy zbierać anonimowe, zagregowane dane analityczne (np. które funkcje są używane i jak często) w celu ulepszania aplikacji. Te dane nie pozwalają na identyfikację osoby. Nie wyświetlamy reklam.

Usługi zewnętrzne

Pealo korzysta z następujących usług zewnętrznych, z których każda podlega własnej polityce prywatności: Google Calendar API (synchronizacja wydarzeń), Microsoft Graph API (synchronizacja wydarzeń), Anthropic API (przetwarzanie komend głosowych), Apple Push Notification service (wyzwalanie synchronizacji alarmów) oraz Railway (hosting serwera).

Bezpieczeństwo danych

Tokeny OAuth są szyfrowane w spoczynku przy użyciu AES-256-GCM. Cała komunikacja między aplikacją, naszym serwerem i usługami zewnętrznymi używa HTTPS/TLS. Tokeny bearer są przechowywane w iOS Keychain.

Przechowywanie i usuwanie danych

Gdy usuniesz konto lub odłączysz kalendarz, powiązane tokeny i metadane są trwale usuwane z naszego serwera. Możesz zażądać pełnego usunięcia danych w dowolnym momencie, kontaktując się z nami.

Udostępnianie i ujawnianie danych

Nie sprzedajemy, nie wynajmujemy ani nie udostępniamy Twoich danych osobowych stronom trzecim w celach marketingowych lub reklamowych. Dane z Google Calendar otrzymane przez Google API są udostępniane, przekazywane lub ujawniane następującym podmiotom, wyłącznie w celu zapewnienia podstawowej funkcjonalności Pealo:

Żadne dane użytkownika Google nie są udostępniane, przekazywane ani ujawniane żadnym innym stronom trzecim.

Google API — ograniczone użycie

Wykorzystanie i przekazywanie przez Pealo informacji otrzymanych z interfejsów API Google będzie zgodne z Polityką danych użytkownika usług API Google, w tym z wymogami ograniczonego użycia. W szczególności:

Twoje prawa (RODO)

Jeśli przebywasz w Europejskim Obszarze Gospodarczym, masz prawo do dostępu, sprostowania lub usunięcia swoich danych osobowych oraz do ograniczenia lub sprzeciwienia się ich przetwarzaniu. Ponieważ przechowujemy jedynie losowy identyfikator i zaszyfrowane tokeny bez profilu osobowego, najprostszym sposobem realizacji tych praw jest usunięcie konta w aplikacji lub kontakt z nami. Naszą podstawą prawną przetwarzania jest uzasadniony interes (świadczenie usługi, o którą poprosiłeś).

Dzieci

Pealo nie jest skierowane do dzieci poniżej 13 roku życia. Nie zbieramy świadomie danych od dzieci.

Kontakt

Pytania dotyczące prywatności: privacy@pealo.app

Grzegorz Mróz Ventures
Krajewskiego 1/29
01-520 Warszawa, Poland